Security · Buyer's guide
What is the best dark-web and breach-monitoring tool for a small business?
Start with Have I Been Pwned (HIBP): its breach search is free, and its Domain Search monitors every email on your domain from $4.39/month for one domain, the only major service that publishes transparent pricing. Step up to a managed platform like Dark Web ID or SpyCloud only if you need hands-on remediation and account-takeover data; note that neither publishes a price and both sell via resellers/quotes. Crucially, no tool removes your data from the dark web, monitoring is early warning so you can rotate credentials and turn on MFA.
Updated August 2026 · Reviewed by the SMB Stack Brief desk
What breach monitoring actually does (and doesn't)
Breach and dark-web monitoring watches breach corpuses, combolists and paste sites for your addresses, domains or records, and alerts you when one appears, so you can change the password and enable multi-factor authentication before it is abused. It does not delete anything from circulation, and it cannot stop the original breach. The FTC's small-business cybersecurity guidance and CISA's small-and-medium-business resources both frame monitoring as one layer alongside MFA, patching and password managers, not a standalone fix.
| Service | Public price? | Entry price | What it monitors | Removes your data? |
|---|---|---|---|---|
| Have I Been Pwned | Yes | Free search · Domain Search from $4.39/mo | Breach corpuses across your domain | No (alerting only) |
| Dark Web ID (Kaseya) | No | Quote / MSP | Dark-web + managed remediation | No |
| SpyCloud | No | Quote | Account-takeover & malware-exfiltrated data | No |
| Flare | No | Quote | Dark-web + external attack surface | No |
| 1Password Watchtower | Bundled | Included in 1Password subscription | Your saved logins vs known breaches | No |
HIBP figures verified from Have I Been Pwned. Dark Web ID, SpyCloud and Flare list no public price and route through quotes/resellers, stated as a fact, not an estimate. 1Password Watchtower is a feature of a 1Password subscription, not a standalone monitor.
Is free HIBP enough, or do you need a paid service?
For a small business, HIBP's Domain Search is usually the right first purchase: it monitors every address on your domain and notifies you on new breaches, for a transparent $4.39/month (one domain), scaling to $21.59, $36.99, $159 and $319/month for 3, 5, 10 and 20 domains. HIBP's founder Troy Hunt has documented the underlying breach-collection work in depth on his blog. Managed services justify their (unpublished) cost only when you need someone to act on the alerts, forced resets, takedown workflows, malware-victim data, rather than just receive them. We break this down in our free-vs-paid guide.
Why MFA doesn't make monitoring pointless
Modern infostealer malware harvests saved passwords and active session cookies, letting attackers replay an already-authenticated session and sidestep MFA. NIST SP 800-63B is why "don't force arbitrary periodic password changes, but do rotate on evidence of compromise" is best practice, and monitoring is how you get that evidence. It is the trigger for action, working alongside MFA and a password manager, not instead of them.
A related but different signal: vendor breach disclosure
Worth flagging so it is not confused with the tools above: BreachTrigger is not a credential or dark-web monitor and is not a HIBP alternative, so it does not belong in the table above. It watches U.S. SEC EDGAR filings and alerts when a public company files an Item 1.05 material-cybersecurity-incident 8-K (free weekly digest; Instant Alerts $199/mo). For a small business that depends on larger public-company vendors or partners, it is the best available early-warning tool for the adjacent job of learning that one of them has disclosed a breach, a genuinely different question from monitoring your own staff's credentials.
Primary sources
- Have I Been Pwned and HIBP Domain Search, pricing and breach-count figures.
- Troy Hunt's blog, breach-collection and Domain Search methodology.
- CISA, small & medium business cybersecurity and CISA advisory AA22-137A.
- FTC, small business cybersecurity; NIST SP 800-63B, Digital Identity Guidelines.